Trojan

Trojan:Win32/WipMBR.A information

Malware Removal

The Trojan:Win32/WipMBR.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WipMBR.A virus can do?

  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/WipMBR.A?


File Info:

name: BAA9862B027ABD61B3E1.mlw
path: /opt/CAPEv2/storage/binaries/f1710c802ce590bc737eda6d1845f390a7e7d2cf43313c3362768c5f9f94a807
crc32: 4C963471
md5: baa9862b027abd61b3e19941e40b1b2d
sha1: bb7587ed63b7d2f429fb471d3c9c44009feb6d77
sha256: f1710c802ce590bc737eda6d1845f390a7e7d2cf43313c3362768c5f9f94a807
sha512: e4b6d09c7a0f02f8df580e160a0c98df5440175dfdbc359a0e9171c78b930d0f5f99f0458eb7cf597ba0c602e1efa611461f84d56a63d93bb10f28227bd7ecb3
ssdeep: 6144:ftt94XjxSHF/pubJmeYkOAEH3uZHphr04FQ+MZSpL9ZTZPWOHvH:D94zx4Ib5m/H3uvGn+NplWuv
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1EF64239824EFC079F053CEB61C0871597179BB9082CEBB1999B1541E1AF00DAE72BFA5
sha3_384: 4d30385fa78d3a67df597d0141e58088de997837de964f7c6f68e420b2513645bd7c040fa5f6dec36eac603a5c84f55d
ep_bytes: 60be00a04a008dbe0070f5ff57eb0b90
timestamp: 2012-08-09 22:46:22

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Distributed Link Tracking Server
FileVersion: 5.2.3790.0 (srv03_rtm.030324-2048)
InternalName: Distributed Link Tracking Server
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: trksvr
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.2.3790.0
Translation: 0x0409 0x04b0

Trojan:Win32/WipMBR.A also known as:

BkavW32.Common.11BB2C58
LionicTrojan.Win32.DistTrack.4!c
DrWebTrojan.KillMBR.165
MicroWorld-eScanGen:Trojan.Heur.umKfIrWRshi
ClamAVWin.Trojan.DistTrack-1
FireEyeGen:Trojan.Heur.umKfIrWRshi
SkyhighBehavesLike.Win32.Fake.fc
McAfeeArtemis!BAA9862B027A
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.EraseMBR.Win32.25
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00479b491 )
AlibabaTrojan:Win32/EraseMBR.ea5a0ef5
K7GWTrojan ( 00479b491 )
ArcabitTrojan.Heur.umKfIrWRshi
BitDefenderThetaAI:Packer.55B1209A1B
SymantecW32.Disttrack
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/DistTrack.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.EraseMBR.a
BitDefenderGen:Trojan.Heur.umKfIrWRshi
NANO-AntivirusTrojan.Win64.DistTrack.vonlx
AvastWin32:Dh-A [Heur]
TencentWin32.Trojan.Erasembr.Jcnw
TACHYONTrojan/W32.EraseMBR.989184
EmsisoftGen:Trojan.Heur.umKfIrWRshi (B)
F-SecureTrojan.TR/Patched.Gen
VIPREGen:Trojan.Heur.umKfIrWRshi
TrendMicroWORM_DISTTRACK.SMA
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.aimyw
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Patched.Gen
Antiy-AVLTrojan[APT]/Win32.Shamoon
Kingsoftmalware.kb.b.985
XcitiumVirus.Win32.DistTrac.A@4qbrmx
MicrosoftTrojan:Win32/WipMBR.A
ViRobotTrojan.Win32.EraseMBR.989184[UPX]
ZoneAlarmTrojan.Win32.EraseMBR.a
GDataGen:Trojan.Heur.umKfIrWRshi
VaristW32/Trojan.KCYX-4657
AhnLab-V3Win-Trojan/Disttrack.989184
VBA32Trojan.Tarkserv.18805
ALYacTrojan.DistTrack.A
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallWORM_DISTTRACK.SMA
RisingTrojan.KillMBR!1.656F (CLOUD)
YandexTrojan.GenAsa!rCXhwEU5jtM
IkarusTrojan.Win32.EraseMBR
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.21CC94!tr
AVGWin32:Dh-A [Heur]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/WipMBR.A?

Trojan:Win32/WipMBR.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment